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Abstract 

A relativistic quantum information exchange protocol is proposed allowing two distant users to 
realize "coin tossing" procedure. The protocol is based on the point that in relativistic quantum 
theory reliable distinguishing between the two orthogonal states generally requires a finite time 
depending on the structure of these states. 

^ ■ PACS numbers: 03.67.-a, 03.65.Bz, 42.50Dv 

Qv^ , The coin tossing protocol is one of the simplest cryptographic protocol and can be described in 

On I the following way. Suppose that two mistrustful parties, A and B, wish to produce a random bit, 

e.g. employing a coin tossing procedure or random numbers generator producing or 1 with equal 

Q . probabilities. Zero outcome means that the participant A won, and outcome 1 means that he lost. If 

^j I A and B are not spatially separated the task is trivial. However, if A and B are located at distant 

ly-v ■ sites and can only exchange information through a communication channel the problem could even 

CN . seem unsolvable since both A and B seem to be able to cheat without being detected. 

^^ \ For the case when A and B can only exchange information through a classical communication 

^ ■ channel the problem was solved by Blum [1]. Strictly speaking, the protocol suggested in Ref.[l] is 

■^ ■ not secure against the cheating of one of the parties since it is based on the unproven computational 

SIJ [ complexity of the discrete logarithm problem [1] . For example, if one of the participants had a quantum 

t^ ' computer (which has not yet been actually built), he could always win due to a fast computation of 

the discrete logarithm [2,3]. 

However, if there exists a quantum communication channel between users A and B, it is possible 
to realize various information exchange protocols whose security is based on the fundamental laws of 
O ■ nature (quantum theory) rather than the computational complexity. Different protocols have been 

^ , suggested and studied so far: quantum key distribution [4-6], quantum bit commitment [7-9], quantum 

C I coin tossing [10], quantum gambling [11], and quantum secret sharing [12]. 

^ ' It was shown earlier that the ideal quantum coin tossing protocol is impossible in the framework 

Q^. of the non-relativistic quantum mechanics [13,14]. (The protocol is said to be ideal if the probability 

^ I of accepting of absence of cheating by both parties is exactly one, and both outcomes and 1 occur 

with equal probabilities of 1/2.) However, a protocol can be designed in which the absence of cheating 
is accepted by both parties with a probability arbitrarily close to one [10]. 
5^ I Recently, a bit commitment protocol and coin tossing protocol were proposed which take into 

account the finite speed of signal propagation. In these protocols, the information is carried by the 
classical states. These protocols assume that the two parties A and B each have a couple of spatially 
separated sites fully controlled by them (for details, see Ref.[15]). In our opinion, this scheme implicitly 
assumes the existence of a communication channel between the sites Ai and A2 (as well as between Bi 
and B2) which is secure against the substitution of information transmitted through it (impersonation) 
or reqires prior sharing of a key string (or afterwards physically getting together to compare notes). 
Proposed below is an example of the real time relativistic coin tossing protocol. 
All quantum cryptographic protocols actually employ the following two features of quantum theory. 
The first one is the no cloning theorem [16], i.e. the impossibility of copying of an arbitrary quantum 
state which is not known beforehand or, in other words, the impossibility of the following process: 

\Am^u{\A)m = \B^m\i;), 

where \A) and \B^) are the apparatus states before and copying act, respectively, and U is a unitary 
operator. Such a process is prohibited by the linearity and unitary nature of quantum evolution. 
Actually, even a weaker process of obtaining any information about one of the two non-orthogonal 
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states without disturbing it is impossible, i.e. the final states of the apparatus \A^-^) and {A^^) 
corresponding to the initial input states |^i) and \ip2), respectively, after the unitary evolution U, 

|^)|V^i)^C/(|A)|Vi)) = |A^,)|Vi), 

\A)\i;2)^U{\A)\i^2)) = \A^,)\i^2), 

can only be different, \A^-^) ^ \A^^), if (^ilV'2) 7^ [17], which means the impossibility of reliable 
distinguishing between non-orthogonal states. There is no such a restriction for orthogonal states. 
That is why almost all cryptographic protocols employ non-orthogonal states as information carriers, 
the only exception being the protocol suggested in Ref.[18]. 

Two orthogonal states can be reliably distinguished, and within the framework of non-relativistic 
quantum mechanics this can be done instantly. It is this circumstance that is actually behind the 
impossibility of designing a cryptographic protocol based on a pair of orthogonal states within the 
framework of non-relativistic quantum mechanics. 

However, in the relativistic quantum field theory the situation is different. The physical field 
observables associated with the two points separated by a space-like interval cannot have any causal 
relations and the commutator of field operators is zero outside the light cone [19]: 

[■u~(xi),u+(x2)]± = -iD~{xi - X2), (1) 

where u^{x) are the field operators, xi^2 are the points of the four-dimensional space-time, and D~{xi — 
X2) is the negative-frequency commutator function [19]. This circumstance imposes a restriction on 
the time required for a reliable (in a single measurement act) distinguishing of a pair of orthogonal 
states. 

Before describing the protocol, we shall first discuss the states and measurements it employs. Any 
one-particle state of the field can be represented in the form 

IV'1,2) = J i^iMKv" - m^)u+ip)dp\0), (2) 

where the integration is performed over the mass surface, "01,2 (p) is the field amplitude, and |0) is 
the vacuum state. In the rest of the paper we shall deal with the massless particles (e.g. photons). 
Therefore, the field operator u~^(p) will be interpreted as the creation operator of a photon in the 
Coulomb gauge. We shall also assume that the amplitudes V'i,2(p) are chosen in such a way that the 
states IV'1,2) are orthogonal: 

+ /_-Mn\ c^p'c^P /■.,.*/_N.,. /_X ^P 



(V1IV2) = / / V'i(p )V'2(p)(o|n-(p )n+(p)|o) " " = / rAp)Mp)7r^ = 0, (3) 

•^ ^ y^2poV2^ -^ ^Po 

[u'ip'),u+{p)U = 6ip'-p). 

In contrast to the non-relativistic quantum mechanics, a detailed consistent theory of measurement in 
quantum field theory has not yet been developed. For the one-particle states, we shall take advantage 
of the analogy with the non-relativistic case. A measurement allowing to distinguish between the two 
orthogonal states is given by the following partition of unity in the subspace of one-particle states: 

Vi+V2+r±=I, V±=I-Vi-V2, ViV, = 5,JV^, (4) 

J = |n+(p)|0)(0|n-(p')^, Pi,2= ('/Vi,2(p')n+(p')|0)^') ^j {Q\u' {p)4,l^{p)^^ (5) 
For the input state \ipi), the probabilities of obtaining different results are 

Pri(Vi) = (VilT^ilV'i) = 1, Pr2,±(^i) = (V'i|7^2,±|V'i> = 0, (6) 



and similarly for the input state |^2)- The measurement defined by Eqs.(4,5) is non-local in the 
sense that it requires access to the whole region of space where the measured field is present. It is 
intuitively clear that if we are dealing with the electromagnetic field in an extended region of space (i.e. 
the analyzed state is characterized by non-zero quantum-mechanical averages of the field operators 
throughout that region at a certain moment of time) , the determination of the field state the measuring 
apparatus should be able to probe the field at an arbitrary point of the whole region. Even if at any 
particular point the information characterizing the field state gathered due to the local interaction 
between the field and the measuring apparatus arises instantly, the transfer of that information from 
all the points to a single observer located at a certain point of space still requires some time. It is 
obvious that wherever is the observer, this time cannot be less than L/2c, where c is the speed of light 
and L is the diameter of the region of non-zero field. Note that a similar situation also takes place for 
the systems described by non-relativistic quantum mechanics if one takes into account the finite speed 
of information transfer. Indeed, consider a composite system consisting of two (non-interacting) two- 
level subsystem (particles 1 and 2) located at two different points separated by distance L. Suppose 
each of these particles can be found in one of the two orthogonal basis states known beforehand. Then, 
to determine the state of the entire composite system, one should perform the measurements on both 
particles. Even if each of these measurements can be carried out instantly, the information on their 
outcomes cannot be conveyed to a single user, wherever he is located, in time shorter than L/2c. 

It is only important for the protocol suggested below that in the relativistic case two orthogonal 
states can only be reliably distinguished in a finite time which depends on their structure. In other 
words, orthogonal states are efficiently indistinguishable (cannot be distinguished reliably) during a 
certain finite time interval and become reliably distinguishable after that time elapses. 

To obtain information on the field state, the measurement should probe the entire region of space 
where the field is localized. Therefore, if initially the field is prepared in a region which is inaccessible 
for one of the parties and then propagates to the region accessible for his measuring apparatus, the 
state becomes completely accessible only in a finite time. The propagation amplitude satisfy the 
causality principle 

d 9 _ 

(V'l,2(xi)|V'l,2(^2)> = -#i^2(-^^)^l,2(^^)^0 (^1 - ^2), (7) 

where Dq{x) is the negative-frequency function 

Doix) = j^ J dk6{P)e{-k^) exp (ikx) = ^e(x°)5(A), (8) 

e(a;°) = 0(x°)-^(-x°), \^ = {x'^f - ^^^ (9) 

here |V'i,2(a^)) is the state in the "x" -representation 

|V'i,2(5)) = /Vi,2(p)e^^"n+(p)^|0). (10) 



Note that for xi = X2 

Pri,2(V'l,2) = (^-1,2 17^1,21^1,2) = KV'l,2(xi)|V'l,2(x2))Ui=£j' = (H) 
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In spite of the product of two singular distributions {Dq (x) = —Dq{—x)) occurring at x^ = in 
Eq.(ll), such a product is a correctly defined distribution since the convolution of two distributions 
whose supports lie in the front part of the light cone always exists [19]. 

Let us now describe the protocol. The parties agree beforehand on the states |V'i) and IV'2) corre- 
sponding to and 1, respectively. The protocol starts at t = when both parties begin the preparation 
of N states (the number A^ is also agreed upon beforehand). The worst case is realized when each user 



(party), on the one hand, possesses a complete control of only the nearest neighbourhood of his own 
laboratory and, on the other hand, can deploy his equipment in the immediate vicinity of the labora- 
tory of the other party in an attempt to cheat him. This means that the protocol should be stable in 
the situation when one of the users (parties) can instantly convey information to the other user, i.e. 
when the length of the communication channel between them is effectively zero. It is actually sufficient 
to require that the efficient size of the region of space where the state is localized substantially exceeds 
the communication channel length. Formally, the situation where the communication channel length 
is zero is equivalent to the case where the parties cannot control the space beyond the immediate 
vicinity of their laboratories located around the points xa,b- At t = each user turns on the source 
of states iV'i) and IV'2) chosen for the communication which immediately start to propagate into the 
communication channel and thus become accessible for the measurements. Reliable distinguishability 
(or distinguishability with the probability arbitrarily close to unit) requires finite time T. The reliable 
distinguishability can be achieved employing the measurement described by Eqs.(4,5). 

After the time T/2 elapses, user A discloses to user B one half {N/2) of the states he has just sent 
to him. When this information reaches B, he discloses his N/2 states to A, and only after obtaining 
this classical information from B user A discloses the remaining N/2 states. Finally, B discloses his 
remaining N/2 states. 

At this stage each user can check consistency between the outcomes of the quantum-mechanical 
measurements performed by him and the data publicly announced by his counterpart. Each single 
fault, e.g. when user A announced that his i-th state was |V'i) (0) while user B had his detector tuned 
to IV'2) (1) firing means that the protocol is aborted. The exchange of classical information and reliable 
distinguishability of orthogonal quantum states make the substitution of even a single bit impossible 
which will be important for the subsequent calculation of the parity bit. 

Then, if after the exchange of classical information, both parties agree in the absence of cheating 
(classical information is fully consistent with the outcomes of quantum measurements) the parity bit 
c = ci © C2 © . . . Cat {ci = ai® bi, ai, bi are the bits sent by A and B, respectively) is calculated which 
is the required random bit the parties A and B wished to generate. 

Let us now discuss possible cheating strategies, e.g. for user A. 

First of all, exchange of classical information is necessary to exclude the possibility of immediately 
re-sending by user A the states he received from B without even trying to analyze them. For the 
case of photons the latter would mean using a mirror mounted by user A just at the point where the 
quantum communication channel used by user B to send his states to user A leaves his laboratory (i.e. 
at xb)- If the parties had agreed beforehand, for example, that the random bit equal to zero means 
that user A wins, he could always cheat by simply re-sending the states obtained from B back to him 
without even trying to analyze them were it not for the necessity to disclose the classical information 
on the states he sent to B later. Indeed, the parity bit in that case would clearly always be zero (A 
wins) since a^ = 5j, q = a^ © ftj = 6j © 6j = 0, c = ci © C2 © . . . cat = 0. On the other hand, if user A 
has to announce through the classical communication channel which states he actually sent to B, this 
strategy obviously fails because of the no-cloning theorem. 

The alternating disclosure of a half of states through a classical communication channel is necessary 
to eliminate the following cheating strategy. Since user B controls only the immediate vicinity of his 
laboratory (point xb), user A can deploy his equipment near xb and, after re-sending quantum states 
back to B, at the stage of exchanging classical information user A can almost instantly send back to B 
the information received from him through the classical channel. Had user B unveiled all the N states 
(which user A sent back to him), user A would be able to send instantly back to him the classical 
information received. The two-stage disclosure of the sent states (one half at a time) allows to detect 
that kind of cheating. 

It is important for the protocol that the states are quantum. If the states were classical, the user 
A could always evade the no-cloning theorem by using an infinitesimal fraction of each state sent to 
him by user B to measure that state (which is not prohibited in classical physics) while simultaneously 
sending back these states back to B without disturbing them. The collected infinitesimal fraction of 
the states could be used to analyze them during the time T and the information obtained could be 



sent to user B at the stage of exchange of classical information. In that case user A always wins. For 
the quantum states this strategy is impossible since any measurement disturbs the quantum states. 

Since the reliable distinguishability of two orthogonal states requires a finite time T, during the 
time interval <t <T the states are effectively non-distinguishable (cannot be distinguished reliably). 
The probability of the correct state identification, i.e. the probability of the corresponding detector 
firing in the time interval (0,t), is an increasing function of time p{t) {p{0) = 0, p{T) = 1). The 
specific form of function p{t) depends on the particular choice of the states and is unimportant in our 
analysis. The user A cannot delay sending of his states since then all should be detected during the 
time T and if they are delayed and A^ ^ 1 there will be detection events beyond the time interval 
< t < T). One of the possible cheating strategies could consist in correcting the states whose 
transmission had already been started by user A depending on the outcomes of the measurements 
performed over the states received from B. In that case user A should already have the outcome of the 
measurement performed over a state sent by B at his disposal by a certain moment t (which occurs 
with the probability p{t)) while the user B should have not yet detected the state sent to him by user 
A (which occurs with the probability 1 — p{t)). The probability of successful cheating is therefore 

Pcheating=p{t){'^-P{t))- (12) 

The maximum of P is reached at p{tc) = 1/2 where P = 1/4 which is less than the probability of 
simple guessing which is 1/2. Therefore, the probability of correct calculation of the parity bit encoded 
in the states sent by B is P^ = (1/4)^. Generally, user A could perform a collective measurement 
over all A'^ states sent to him by B simultaneously. Because of the effective non-orthogonality of the 
states during the time interval T the probability of success (see e.g. Ref. [20] on the optimal detection 
of the parity bit) in that case is vP^ = (1/2) which is again not better than simply guessing at the 
parity bit. 

We conclude with the following remark. The possibility of a reliable identification of a state during 
a finite time interval T depends on whether or not there exist the states with a finite spatial support for 
the chosen type of particles. In the case of photons only the exponentially (with respect to the energy 
density and detection rate) localized states are currently known to exist [21]. The latter formally 
means that the reliable identification (with the probability strictly equal to 1) can only be achieved 
with an infinite time interval. However, this consideration does not impose any substantial restrictions 
on the protocol since the time interval can be chosen sufficiently long to ensure the exponentially close 
to unity probability of the distinguishability of two orthogonal states. 
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tic protocols [15]. This work was supported by the Russian Foundation for Basic Research (project No 
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